FILEMembers
FILE

APT28 Cracked-Software Lure Rode 16-Month-Old C2 Infrastructure

A single Windows executable posing as five pirated applications reached 37 submission sources in twelve days, backed by C2 infrastructure assembled more than a year before the payload appeared. The campaign, attributed to Russian state-aligned APT28, deploys a stealer-trojan with layered evasion that partially defeated automated sandbox analysis.

Jun 20, 2026, 16:47 (UTC+9)Last seenJun 20, 2026Severity77ByCTX TeamActorAPT28StrontiumIOC6MITRE11RegionsBDBRCACLCR

A single Windows executable masquerading as five popular pirated applications reached 37 independent submission sources within twelve days of its first appearance — not because the operator rushed the deployment, but because the infrastructure waiting to receive it had been quietly assembled more than a year in advance. The C2 certificate was minted in January 2025. The domains were batch-registered in April 2026. The payload surfaced in June 2026.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence